Splunk Enterprise

Upload traffic log Palo Alto

wahluf
Explorer

i am a beginner in using splunk. I'm doing research on log traffic from Palo Alto. inside i upload data to splunk. what is the most appropriate sourcetype for me to choose?

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

you are probably using this app: Palo Alto Networks App for Splunk and add-on Palo Alto Networks Add-on for Splunk for getting logs in. Just look from App's instruction how to use it. I think that most sourcetypes are named like pan:xxx

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you are probably using this app: Palo Alto Networks App for Splunk and add-on Palo Alto Networks Add-on for Splunk for getting logs in. Just look from App's instruction how to use it. I think that most sourcetypes are named like pan:xxx

r. Ismo

View solution in original post

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.